Care One Pharmacy Services Global Privacy Policy

This Privacy Policy statement is made by the Care One Pharmacy Services and

includes the elements associated to all services and products offered by Care One

Pharmacy Services (collectively, “CareOne”, “we”, “us”, “our”).

CareOne’s Privacy Commitment

We ask for only the least amount of information necessary, gathering only what we

believe is essential for doing business, or for the specific transaction at hand. We let

customers know the information we have on them and allow them to opt out of specific

engagements. But, by far, our biggest commitment is that we do not make a single

dollar from advertising revenue—never have, never will—even from the free editions of

our products. This means we avoid the fundamental conflict of interest between

gathering customer information and fueling advertising revenue, and the unavoidable

compromises in customer privacy that it brings.

The goal of this policy is to make explicit the information we gather, how we will use it,

and how we will not. This policy is unfortunately longer than we would like, but we must

unambiguously address all the relevant cases. We will try and keep the language simple

and direct as much as possible.

Scope of this Privacy Policy

This Privacy Policy applies to all CareOne websites that link to it. It also applies to the

products and services provided by CareOne through these websites. This Privacy

Policy does not apply to any of our websites, products or services that have a separate

privacy policy.

This Privacy Policy is divided into three parts:

Part I – Information CareOne collects and controls

This part deals with how CareOne collects and uses information about website visitors,

potential customers, users of CareOne’s products and services, and others who contact

CareOne through forms or email addresses published on or linked to our websites.

Part II – Information that CareOne processes on your behalf

This part deals with how CareOne handles data that you entrust to us when using our

products and services, or when you share any personal or confidential information with

us while requesting customer support.

Part III – General

This part deals with topics that are relevant to both Parts I and II, and other general

topics such as CareOne’s security commitments and how we will inform you when we

change this Privacy Policy.

Part I – Information CareOne collects and controls

What information CareOne collects

We collect information about you only if we need the information for some legitimate

purpose. CareOne will have information about you only if (a) you have provided the

information yourself, (b) CareOne has automatically collected the information, or (c)

CareOne has obtained the information from a third party. Below we describe the various

scenarios that fall under each of those three categories and the information collected in

each one.

Information that you provide us

i. Account signup: When you sign up for an account to access one or more of our

services, we ask for information like your name, contact number, email address,

company name and country to complete the account signup process. You’ll also be

required to choose a unique username and a password for accessing the created

account. You may also provide us with more information such as your photo, time zone

and language, but we don’t require that information to sign up for an account. After

signing up, you will have the option of choosing a security question and an answer to

the security question — if you provide these, they will be used only while resetting your

password.

ii. Event registrations and other form submissions: We record information that you

submit when you (i) register for any event, including webinars or seminars, (ii) subscribe

to our newsletter or any other mailing list, (iii) submit a form in order to download any

product, whitepaper, or other materials, (iv) participate in contests or respond to

surveys, or (v) submit a form to request customer support, get a quote or to contact us

for any other purpose.

iii. Payment processing: When you buy something from us, we ask you to provide

your name, contact information, and credit card information or other payment account

information. When you submit your card information, we store the name and address of

the cardholder, the expiry date and the last four digits of the credit card number. We do

not store the actual credit card number. For quick processing of future payments, if you

have given us your approval, we may store your credit card information or other

payment information in an encrypted format in the secured servers of our Payment

Gateway Service Providers.

iv. Testimonials: When you authorize us to post testimonials about our products and

services on websites, we may include your name and other personal information in the

testimonial. You will be given an opportunity to review and approve the testimonial

before we post it. If you wish to update or delete your testimonial, you can contact us

at info@CareOnerx.com

v. Interactions with CareOne: We may record, analyze and use your interactions with

us, including email, telephone, and chat conversations with our sales and customer

support professionals, for improving our interactions with you and other customers.

Information that we collect automatically

i. Information from browsers, devices and servers : When you visit our websites, we

collect information that web browsers, mobile devices and servers make available, such

as the internet protocol address, browser type, language preference, time zone,

referring URL, date and time of access, operating system, mobile device manufacturer

and mobile network information. We include these in our log files to understand more

about visitors to our websites.

ii. Information from cookies and tracking technologies: We use temporary and

permanent cookies to identify users of our services and to enhance user experience.

We embed unique identifiers in our downloadable products to track usage of the

products. We also use cookies, beacons, tags, scripts, and other similar technologies to

identify visitors, track website navigation, gather demographic information about visitors

and users, understand email campaign effectiveness and for targeted visitor and user

engagement by tracking your activities on our websites. We mostly use first-party

cookies and do not use third-party cookies or other third-party tracking technologies on

our websites for non-essential or intrusive tracking.

iii. Information from application logs and mobile analytics : We collect information about

your use of our products, services and mobile applications from application logs and in-

house usage analytics tools, and use it to understand how your use and needs can

improve our products. This information includes clicks, scrolls, features accessed,

access time and frequency, errors generated, performance data, storage utilized, user

settings and configurations, and devices used to access and their locations.

Information that we collect from third parties

i. Referrals: If someone has referred any of our products or services to you through any

of our referral programs, that person may have provided us your name, email address

and other personal information. You may contact us at info@CareOnerx.com to request

that we remove your information from our database. If you provide us information about

another person, or if another person gives us your information, we will only use that

information for the specific reason for which it was provided to us.

iii. Information from our reselling partners and service providers: If you contact any of

our reselling partners, or otherwise express interest in any of our products or services to

them, the reselling partner may pass your name, email address, company name and

other information to CareOne. If you register for or attend an event that is sponsored by

CareOne, the event organizer may share your information with us. CareOne may also

receive information about you from review sites if you comment on any review of our

products and services, and from other third-party service providers that we engage for

marketing our products and services.

iv. Information from social media sites and other publicly available sources: When you

provide feedback or reviews about our products, interact, or engage with us on

marketplaces, review sites or social media sites such as Facebook, Twitter, LinkedIn

and Instagram through posts, comments, questions and other interactions, we may

collect such publicly available information, including profile information, to allow us to

connect with you, improve our products, better understand user reactions and issues, or

to reproduce and publish your feedback on our websites. We must tell you that once

collected, this information may remain with us even if you delete it from these sites.

CareOne may also add and update information about you, from other publicly available

sources.

Purposes for using information

In addition to the purposes mentioned above, we may use your information for the

following purposes:

  To communicate with you (such as through email) about products that you have

downloaded and services that you have signed up for, changes to this Privacy

Policy, changes to the Terms of Service, or important notices;

  To keep you posted on new products and services, upcoming events, offers,

promotions and other information that we think will be of interest to you;

  To ask you to participate in surveys, or to solicit feedback on our products and

services;

  To set up and maintain your account, and to do all other things required for

providing our services, such as enabling collaboration, providing website and

mail hosting, and backing up and restoring your data;

  To understand how users use our products and services, to monitor and prevent

problems, and to improve our products and services;

  To provide customer support, and to analyze and improve our interactions with

customers;

  To detect and prevent fraudulent transactions and other illegal activities, to

report spam, and to protect the rights and interests of CareOne, CareOne’s

users, third parties and the public;

  To update, expand and analyze our records, identify new customers, and

provide products and services that may be of interest to you;

  To analyze trends, administer our websites, and track visitor navigations on our

websites to understand what visitors are looking for and to better help them;

  To monitor and improve marketing campaigns and make suggestions relevant to

the user.

Legal bases for collecting and using information

Legal processing bases applicable to CareOne: If you are an individual from the

European Economic Area (EEA), our legal basis for information collection and use

depends on the personal information concerned and the context in which we collect it.

Most of our information collection and processing activities are typically based on (i)

contractual necessity, (ii) one or more legitimate interests of CareOne or a third party

that are not overridden by your data protection interests, or (iii) your consent.

Sometimes, we may be legally required to collect your information, or may need your

personal information to protect your vital interests or those of another person.

Withdrawal of consent: Where we rely on your consent as the legal basis, you have the

right to withdraw your consent at any time, but this will not affect any processing that

has already taken place.

Legitimate interests notice: Where we rely on legitimate interests as the legal basis and

those legitimate interests are not specified above, we will clearly explain to you what

those legitimate interests are at the time that we collect your information.

Your choice in information use

Opt out of non-essential electronic communications : You may opt out of receiving

newsletters and other non-essential messages by using the ‘unsubscribe’ function

included in all such messages. However, you will continue to receive essential notices

and emails such as account notification emails (password change, renewal reminders,

etc.), security incident alerts, security and privacy update notifications, and essential

transactional and payment related emails.

Disable cookies: You can disable browser cookies before visiting our websites.

However, if you do so, you may not be able to use certain features of the websites

properly.

Optional information: You can choose not to provide optional profile information such as

your photo. You can also delete or change your optional profile information. You can

always choose not to fill in non-mandatory fields when you submit any form linked to our

websites.

Who we share your information with

We share your information only in the ways that are described in this Privacy Policy, and

only with parties who adopt appropriate confidentiality and security measures.

Employees and independent contractors: Employees and independent contractors of

relevant CareOne entities have access to the information covered in Part I on a need-to-

know basis. We require all employees and independent contractors of CareOne entities

to follow this Privacy Policy for personal information that we share with them.

Third-party service providers: We may need to share your personal information and

aggregated or de-identified information with third-party service providers that we

engage, such as marketing and advertising partners, event organizers, web analytics

providers and payment processors. These service providers are authorized to use your

personal information only as necessary to provide these services to us.

Other cases: Other scenarios in which we may share the same information covered

under Parts I and II are described in Part III.

Your rights with respect to information we hold about you:

Right to access: You have the right to access (and obtain a copy of, if required) the

categories of personal information that we hold about you, including the information's

source, purpose and period of processing, and the persons to whom the information is

shared.

Right to rectification: You have the right to update the information we hold about you or

to rectify any inaccuracies. Based on the purpose for which we use your information,

you can instruct us to add supplemental information about you in our database.

Right to erasure: You have the right to request that we delete your personal information

in certain circumstances, such as when it is no longer necessary for the purpose for

which it was originally collected.

Right to restriction of processing: You may also have the right to request to restrict the

use of your information in certain circumstances, such as when you have objected to

our use of your data but we need to verify whether we have overriding legitimate

grounds to use it.

Right to data portability: You have the right to transfer your information to a third party in

a structured, commonly used and machine-readable format, in circumstances where the

information is processed with your consent or by automated means.

Right to object: You have the right to object to the use of your information in certain

circumstances, such as the use of your personal information for direct marketing.

Right to complain: You have the right to complain to the appropriate supervisory

authority if you have any grievance against the way we collect, use or share your

information. This right may not be available to you if there is no supervisory authority

dealing with data protection in your country.

Retention of information

We retain your personal information for as long as it is required for the purposes stated

in this Privacy Policy. Sometimes, we may retain your information for longer periods as

permitted or required by law, such as to maintain suppression lists, prevent abuse, if

required in connection with a legal claim or proceeding, to enforce our agreements, for

tax, accounting, or to comply with other legal obligations. When we no longer have a

legitimate need to process your information, we will delete or anonymize your

information from our active databases. We will also securely store the information and

isolate it from further processing on backup discs until deletion is possible.

Part II – Information that CareOne processes on your behalf

Information entrusted to CareOne and purpose

Information provided in connection with services: You may entrust information that you

or your organization (“you”) control, to CareOne in connection with use of our services

or for requesting technical support for our products. This includes information regarding

your customers and your employees (if you are a controller) or data that you hold and

use on behalf of another person for a specific purpose, such as a customer to whom

you provide services (if you are a processor). The data may either be stored on our

servers when you use our services, or transferred or shared to us as part of a request

for technical support or other services.

Information from mobile devices: When you elect to allow it, some of our mobile

applications have access to the camera, microphone, call history, contact information,

photo library, files and other information stored on your mobile device. Our applications

require such access to provide their services. Similarly, when you elect to provide

access, location-based information is also collected for purposes including, but not

limited to, locating nearby contacts or setting location-based reminders. This information

will be exclusively shared with our mapping providers and will be used only for mapping

user locations. You may disable the mobile applications’ access to this information at

any time by editing the settings on your mobile device. The data stored on your mobile

device and their location information to which the mobile applications have access will

be used in the context of the mobile application, and transferred to and associated with

your account in the corresponding services (in which case the data will be stored on our

servers) or products (in which case the data will remain with you unless you share it

with us).

(All the information entrusted to CareOne is collectively termed “service data”)

Ownership and control of your service data

We recognize that you own your service data. We provide you complete control of your

service data by providing you the ability to (i) access your service data, (ii) share your

service data through supported third-party integrations, and (iii) request export or

deletion of your service data.

How we use service data

We process your service data when you provide us instructions through the various

modules of our services. For example, when you generate an invoice using our

invoicing service, information such as the name and address of your customer will be

used to generate the invoice; and when you use our campaign management service for

email marketing, the email addresses of the persons on your mailing list will be used for

sending the emails.

Push notifications

If you have enabled notification on our desktop and mobile applications, we will push

notifications through a push notification provider such as Apple Push Notification

Service, Google Cloud Messaging or Windows Push Notification Services. You can

manage your push notification preferences or deactivate these notifications by turning

off notifications in the application or device settings.

Who we share service data with

CareOne and third party sub-processors : In order to provide services and technical

support for our products, the contracting entity within CareOne engages other group

entities and third parties.

Employees and independent contractors: We may provide access to your service data

to our employees and individuals who are independent contractors of the CareOne

group entities involved in providing the services (collectively our “employees”) so that

they can (i) identify, analyze and resolve errors, (ii) manually verify emails reported as

spam to improve spam detection, or (iii) manually verify scanned images that you

submit to us to verify the accuracy of optical character recognition. We ensure that

access by our employees to your service data is restricted to specific individuals, and is

logged and audited. Our employees will also have access to data that you knowingly

share with us for technical support or to import data into our products or services. We

communicate our privacy and security guidelines to our employees and strictly enforce

privacy safeguards within CareOne.

Collaborators and other user: Some of our products or services allow you to collaborate

with other users or third parties. Initiating collaboration may enable other collaborators

to view some or all of your profile information. For example, when you edit a document

that you have shared with other persons for collaboration, your name and profile picture

will be displayed next to your edits to allow your collaborators to know that you made

those edits.

Third-party integrations you have enabled: Most of our products and services support

integrations with third-party products and services. If you choose to enable any third-

party integrations, you may be allowing the third party to access your service data and

personal information about you. We encourage you to review the privacy practices of

the third-party services and products before you enable integrations with them.

Retention of information

We hold the data in your account as long as you choose to use CareOne Services.

Once you terminate your CareOne user account, your data will eventually get deleted

from active database during the next clean-up that occurs once in 6 months. The data

deleted from active database will be deleted from backups after 3 months.

Part III – General

Children’s personal information

Our products and services are not directed to individuals under 16. CareOne does not

knowingly collect personal information from children who are under 16 years of age for

its own purposes. If we become aware that a child under 16 has provided us with

personal information, we will take steps to delete such information. If you believe that a

child under 16 years has provided personal information to us, please write

to info@CareOnerx.com with the details, and we will take the necessary steps to delete

the information we hold about that child. However, using our products, you can collect

information about individuals who may be children. If you process information relating to

children, you acknowledge and agree that you will be responsible for complying with the

applicable laws and regulations related to protection of such personal information.

How secure is your information

At CareOne, we take data security very seriously. We have taken steps to implement

appropriate administrative, technical and physical safeguards to prevent unauthorized

access, use, modification, disclosure or destruction of the information you entrust to us.

If you have any concerns regarding the security of your data, we encourage you to

check our Security Policy or write to us at info@CareOnerx.com with any questions.

Automation and Artificial Intelligence

In order to provide enhanced productivity and predictive capabilities to our users, we

employ a variety of technologies such as regex parsing, template matching, artificial

intelligence and machine learning. In keeping with CareOne’s promise not to exploit

your data in a way that is not respectful of your privacy and confidentiality expectations,

we make only the following limited use of service data for these technologies: (i) using

anonymized crops of service data to improve accuracy of the algorithms; and (ii) using

your organization’s data for developing models specific for your organization. Our

automation and artificial intelligence technologies are mostly powered by our own

organization’s data such as internal communications, communications with customers

and internal documents as well as free and paid external sources.

Do Not Track (DNT) requests

Some internet browsers have enabled ‘Do Not Track’ (DNT) features, which send out a

signal (called the DNT signal) to the websites that you visit indicating that you don’t wish

to be tracked. Currently, there is no standard that governs what websites can or should

do when they receive these signals. For now, we do not take action in response to these

signals.

External links on our websites

Some pages of our websites may contain links to websites that are not linked to this

Privacy Policy. If you submit your personal information to any of these third-party sites,

your personal information is governed by their privacy policies. As a safety measure, we

recommend that you not share any personal information with these third parties unless

you’ve checked their privacy policies and assured yourself of their privacy practices.

Blogs and forums

We offer publicly accessible blogs and forums on our websites. Please be aware that

any information you provide on these blogs and forums may be used to contact you with

unsolicited messages. We urge you to be cautious in disclosing personal information in

our blogs and forums. CareOne is not responsible for the personal information you elect

to disclose publicly. Your posts and certain profile information may remain even after

you terminate your account with CareOne. To request the removal of your information

from our blogs and forums, you can contact us at info@CareOnerx.com.

Social media widgets

Our websites include social media widgets such as Facebook “like” buttons and Twitter

“tweet” buttons that let you share articles and other information. These widgets may

collect information such as your IP address and the pages you navigate in the website,

and may set a cookie to enable the widgets to function properly. Your interactions with

these widgets are governed by the privacy policies of the companies providing them.

Disclosures in compliance with legal obligations

We may be required by law to preserve or disclose your personal information and

service data to comply with any applicable law, regulation, legal process or

governmental request, including to meet national security requirements.

Enforcement of our rights

We may disclose personal information and service data to a third party if we believe that

such disclosure is necessary for preventing fraud, spam filtering, investigating any

suspected illegal activity, enforcing our agreements or policies, or protecting the safety

of our users.

Business Transfers

We do not intend to sell our business. However, in the unlikely event that we sell our

business or get acquired or merged, we will ensure that the acquiring entity is legally

bound to honor our commitments to you. We will notify you via email or through a

prominent notice on our website of any change in ownership or in the uses of your

personal information and service data. We will also notify you about any choices you

may have regarding your personal information and service data.

Compliance with this Privacy Policy

We make every effort, including periodic reviews, to ensure that personal information

you provide is used in conformity with this Privacy Policy. If you have any concerns

about our adherence to this Privacy Policy or the manner in which your personal

information is used, kindly write to us info@CareOnerx.com. We’ll contact you, and if

required, coordinate with the appropriate regulatory authorities to effectively address

your concerns.

Notification of changes

We may modify the Privacy Policy at any time, upon notifying you through a service

announcement or by sending an email to your primary email address. If we make

significant changes to the Privacy Policy that affect your rights, you will be provided with

at least 30 days’ advance notice of the changes by email to your primary email address.

However, if you have not verified your email address, you may miss important

notifications that we send through email. If you think that the updated Privacy Policy

affects your rights with respect to your use of our products or services, you may

terminate your use by sending us an email within 30 days. Your continued use after the

effective date of changes to the Privacy Policy will be deemed to be your agreement to

the modified Privacy Policy. You will not receive email notification of minor changes to

the Privacy Policy.